CVE-2017-8447: Medium severity elastic vulnerability
An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete and index requests against that index.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8447?
CVE-2017-8447 is rated as a medium severity vulnerability due to improper privilege enforcement that may allow unauthorized actions on indices.
How do I fix CVE-2017-8447?
To fix CVE-2017-8447, upgrade your X-Pack Security version to 5.6.0 or later to ensure proper permission controls.
What impact does CVE-2017-8447 have on my X-Pack Security?
CVE-2017-8447 may allow users with limited permissions to perform unauthorized delete and index operations on indices.
Which versions of X-Pack are affected by CVE-2017-8447?
CVE-2017-8447 affects X-Pack Security versions 5.3.0 to 5.5.2.
How can I determine if my system is vulnerable to CVE-2017-8447?
To determine if your system is vulnerable to CVE-2017-8447, check if you are using X-Pack Security versions 5.3.0 to 5.5.2 and review user permission settings.